Today's Wordle Hints, Answer and Help for June 9, #1816
https://www.cnet.com/tech/gaming/todays-wordle-hints-answer-and-help-for-june-9-1816/
Here are hints and the answer for today's Wordle for June 9, No. 1,816.
https://www.cnet.com/tech/gaming/todays-wordle-hints-answer-and-help-for-june-9-1816/
Here are hints and the answer for today's Wordle for June 9, No. 1,816.
Today's NYT Connections Hints, Answers and Help for June 9, #1094
https://www.cnet.com/tech/gaming/todays-nyt-connections-hints-answers-and-help-for-june-9-1094/
Here are some hints and the answers for the NYT Connections puzzle for June 9, No. 1,094.
https://www.cnet.com/tech/gaming/todays-nyt-connections-hints-answers-and-help-for-june-9-1094/
Here are some hints and the answers for the NYT Connections puzzle for June 9, No. 1,094.
This One MacOS Fix Is Better Than Any of Apple's AI Announcements
https://www.cnet.com/tech/services-and-software/this-one-macos-fix-is-better-than-any-of-apples-ai-announcements/
Commentary: Apple is at last addressing the most un-Apple-like thing about MacOS Tahoe.
https://www.cnet.com/tech/services-and-software/this-one-macos-fix-is-better-than-any-of-apples-ai-announcements/
Commentary: Apple is at last addressing the most un-Apple-like thing about MacOS Tahoe.
Apple Adds Spanish to Workout Buddy, but Could’ve Used More Fitness Upgrades
https://www.cnet.com/health/fitness/wwdc-2026-workout-buddy-update-spanish/
Commentary: Workout Buddy has the potential to be a great fitness app. But without major changes at WWDC 2026, it's not there just yet.
https://www.cnet.com/health/fitness/wwdc-2026-workout-buddy-update-spanish/
Commentary: Workout Buddy has the potential to be a great fitness app. But without major changes at WWDC 2026, it's not there just yet.
Apple Didn't Mention AI for 28 Minutes at WWDC 2026
https://www.cnet.com/tech/services-and-software/apple-didnt-mention-ai-28-minutes-wwdc/
Commentary: The company stuck to using "Apple Intelligence," referencing its own proprietary AI, rather than the two-letter acronym and the negative baggage it carries.
https://www.cnet.com/tech/services-and-software/apple-didnt-mention-ai-28-minutes-wwdc/
Commentary: The company stuck to using "Apple Intelligence," referencing its own proprietary AI, rather than the two-letter acronym and the negative baggage it carries.
Apple's AirPods Are Finally Getting Custom Equalizer Settings
https://www.cnet.com/tech/mobile/apple-airpods-lineup-is-finally-getting-custom-equalizer-settings/
At WWDC 2026, Apple announced that it's bringing a 3-band custom EQ to its latest AirPods this fall, so you can manually tweak their sound to your liking.
https://www.cnet.com/tech/mobile/apple-airpods-lineup-is-finally-getting-custom-equalizer-settings/
At WWDC 2026, Apple announced that it's bringing a 3-band custom EQ to its latest AirPods this fall, so you can manually tweak their sound to your liking.
Apple's New Siri AI Has Customization That Other Voice Assistants Need (Badly)
https://www.cnet.com/home/smart-home/apples-new-siri-ai-brings-customization-other-voice-assistants-badly-need/
The new Siri announced at WWDC 2026 comes with personalization options. My take: Voice assistants like Alexa and Gemini should have had these for years.
https://www.cnet.com/home/smart-home/apples-new-siri-ai-brings-customization-other-voice-assistants-badly-need/
The new Siri announced at WWDC 2026 comes with personalization options. My take: Voice assistants like Alexa and Gemini should have had these for years.
Apple Has a New Search Interface: Here's What This Means For Your iPhone
https://www.cnet.com/tech/services-and-software/apple-announces-new-search-interface-heres-what-this-means-for-your-iphone/
Apple says your iPhone's search results could be faster, more reliable and more accurate.
https://www.cnet.com/tech/services-and-software/apple-announces-new-search-interface-heres-what-this-means-for-your-iphone/
Apple says your iPhone's search results could be faster, more reliable and more accurate.
Tech Experts Break Down Apple's WWDC 2026: Did It Satisfy Apple Fans? video
https://www.cnet.com/videos/tech-experts-break-down-apples-wwdc-2026-did-it-satisfy-apple-fans/
In this special live edition of One More Thing, tech editors from CNET, PCMag and Mashable break down Tim Cook's final Worldwide Developers Conference and ponder whether or not there was enough meat on the bones to satisfy Apple fans and developers.
https://www.cnet.com/videos/tech-experts-break-down-apples-wwdc-2026-did-it-satisfy-apple-fans/
In this special live edition of One More Thing, tech editors from CNET, PCMag and Mashable break down Tim Cook's final Worldwide Developers Conference and ponder whether or not there was enough meat on the bones to satisfy Apple fans and developers.
How to Use AI to Pick the Best Game-Day and Airplane Seats
https://www.cnet.com/tech/services-and-software/how-to-use-ai-to-get-the-best-seat-on-planes-and-at-events/
Game the aisles without paying the up-charge.
https://www.cnet.com/tech/services-and-software/how-to-use-ai-to-get-the-best-seat-on-planes-and-at-events/
Game the aisles without paying the up-charge.
Apple's Upgraded Siri AI Promises to Do More. I'm Not Sure I Want That
https://www.cnet.com/tech/services-and-software/siri-ai-wwdc-2026-can-you-trust-it/
Commentary: I can't trust AI to complete my tasks as I would.
https://www.cnet.com/tech/services-and-software/siri-ai-wwdc-2026-can-you-trust-it/
Commentary: I can't trust AI to complete my tasks as I would.
Apple's WWDC 2026 Recap: Siri Updates and More video
https://www.cnet.com/videos/apples-wwdc-2026-recap-siri-updates-and-more/
CNET's Bridget Carey and Scott Stein share their first impressions immediately following Apple's WWDC 2026 event. What stood out? What fell flat? and what felt left out?
https://www.cnet.com/videos/apples-wwdc-2026-recap-siri-updates-and-more/
CNET's Bridget Carey and Scott Stein share their first impressions immediately following Apple's WWDC 2026 event. What stood out? What fell flat? and what felt left out?
How Was Tim Cook's Final WWDC? video
https://www.cnet.com/videos/how-was-tim-cooks-final-wwdc/
Tech Experts from CNET, PCMag, and Mashable discuss the vibes we felt from WWDC 2026. Was there a passing of the torch from Tim Cook?
https://www.cnet.com/videos/how-was-tim-cooks-final-wwdc/
Tech Experts from CNET, PCMag, and Mashable discuss the vibes we felt from WWDC 2026. Was there a passing of the torch from Tim Cook?
The Devil Wears Prada, and for Artemis IV, So Will Astronauts
https://www.cnet.com/science/space/artemis-iv-nasa-astronauts-spacesuit-prada-axiom-space-moon/
The inner lining on Prada's spacesuits will keep astronauts comfortable and protected from the often harsh temperatures on the moon.
https://www.cnet.com/science/space/artemis-iv-nasa-astronauts-spacesuit-prada-axiom-space-moon/
The inner lining on Prada's spacesuits will keep astronauts comfortable and protected from the often harsh temperatures on the moon.
Tech Editors Discuss the New Siri AI Updates from WWDC 2026 video
https://www.cnet.com/videos/tech-editors-discuss-the-new-siri-ai-updates-from-wwdc-2026/
Tech editors from CNET, Mashable, and PCMag share their first impressions of Apple Intelligence and Siri updates and news from WWDC 2026. Do these updates make the iPhone more desirable and where have seen these features before?
https://www.cnet.com/videos/tech-editors-discuss-the-new-siri-ai-updates-from-wwdc-2026/
Tech editors from CNET, Mashable, and PCMag share their first impressions of Apple Intelligence and Siri updates and news from WWDC 2026. Do these updates make the iPhone more desirable and where have seen these features before?
Stream Every 2026 World Cup Game: A Cord-Cutter's Guide video
https://www.cnet.com/videos/stream-every-2026-world-cup-game-a-cord-cutters-guide/
Want to catch all 104 matches of the 2026 World Cup without a traditional cable subscription? This quick guide breaks down the cheapest ways to stream the games in both English and Spanish using platforms like Fox One and Peacock.
https://www.cnet.com/videos/stream-every-2026-world-cup-game-a-cord-cutters-guide/
Want to catch all 104 matches of the 2026 World Cup without a traditional cable subscription? This quick guide breaks down the cheapest ways to stream the games in both English and Spanish using platforms like Fox One and Peacock.
Apple's Cautious AI Strategy Could Have Been Its Smartest Move
https://www.cnet.com/tech/services-and-software/apple-ai-strategy-wwdc-2026-commentary/
Commentary: Some say Apple is lagging behind in the AI gold rush. I think the company has positioned itself strategically.
https://www.cnet.com/tech/services-and-software/apple-ai-strategy-wwdc-2026-commentary/
Commentary: Some say Apple is lagging behind in the AI gold rush. I think the company has positioned itself strategically.
Popular Wildfire App Watch Duty Expands to Cover Floods Nationwide
https://www.cnet.com/home/security/popular-wildfire-app-watch-duty-expands-to-cover-nationwide-floods/
After helping track fires for years, Watch Duty is aiming to become your disaster go-to with flood coverage straight from the front lines.
https://www.cnet.com/home/security/popular-wildfire-app-watch-duty-expands-to-cover-nationwide-floods/
After helping track fires for years, Watch Duty is aiming to become your disaster go-to with flood coverage straight from the front lines.
XSAs released on 2026-06-09
https://www.qubes-os.org/news/2026/06/09/xsas-released-on-2026-06-09/
The Xen Project (https://xenproject.org/) has released one or more Xen security advisories (XSAs) (https://xenbits.xen.org/xsa/).
The security of Qubes OS is affected.
XSAs that DO affect the security of Qubes OS
The following XSAs do affect the security of Qubes OS:
XSA-491 (https://xenbits.xen.org/xsa/advisory-491.html): See QSB-115 (https://www.qubes-os.org/news/2026/06/09/qsb-115/).
XSAs that DO NOT affect the security of Qubes OS
The following XSAs do not affect the security of Qubes OS, and no user action is necessary:
XSA-492 (https://xenbits.xen.org/xsa/advisory-492.html): Denial of service only
XSA-493 (https://xenbits.xen.org/xsa/advisory-493.html): Only Arm systems are affected. Qubes OS does not run on Arm systems.
XSA-494 (https://xenbits.xen.org/xsa/advisory-494.html): Shadow paging is disabled in Qubes OS at build time.
About this announcement
Qubes OS uses the Xen hypervisor (https://wiki.xenproject.org/wiki/Xen_Project_Software_Overview) as part of its architecture (https://doc.qubes-os.org/en/latest/developer/system/architecture.html). When the Xen Project (https://xenproject.org/) publicly discloses a vulnerability in the Xen hypervisor, they issue a notice called a Xen security advisory (XSA) (https://xenproject.org/developers/security-policy/). Vulnerabilities in the Xen hypervisor sometimes have security implications for Qubes OS. When they do, we issue a notice called a Qubes security bulletin (QSB) (https://www.qubes-os.org/security/qsb/). (QSBs are also issued for non-Xen vulnerabilities.) However, QSBs can provide only positive confirmation that certain XSAs do affect the security of Qubes OS. QSBs cannot provide negative confirmation that other XSAs do not affect the security of Qubes OS. Therefore, we also maintain an XSA tracker (https://www.qubes-os.org/security/xsa/), which is a comprehensive list of all XSAs publicly disclosed to date, including whether each one affects the security of Qubes OS. When new XSAs are published, we add them to the XSA tracker and publish a notice like this one in order to inform Qubes users that a new batch of XSAs has been released and whether each one affects the security of Qubes OS.
https://www.qubes-os.org/news/2026/06/09/xsas-released-on-2026-06-09/
The Xen Project (https://xenproject.org/) has released one or more Xen security advisories (XSAs) (https://xenbits.xen.org/xsa/).
The security of Qubes OS is affected.
XSAs that DO affect the security of Qubes OS
The following XSAs do affect the security of Qubes OS:
XSA-491 (https://xenbits.xen.org/xsa/advisory-491.html): See QSB-115 (https://www.qubes-os.org/news/2026/06/09/qsb-115/).
XSAs that DO NOT affect the security of Qubes OS
The following XSAs do not affect the security of Qubes OS, and no user action is necessary:
XSA-492 (https://xenbits.xen.org/xsa/advisory-492.html): Denial of service only
XSA-493 (https://xenbits.xen.org/xsa/advisory-493.html): Only Arm systems are affected. Qubes OS does not run on Arm systems.
XSA-494 (https://xenbits.xen.org/xsa/advisory-494.html): Shadow paging is disabled in Qubes OS at build time.
About this announcement
Qubes OS uses the Xen hypervisor (https://wiki.xenproject.org/wiki/Xen_Project_Software_Overview) as part of its architecture (https://doc.qubes-os.org/en/latest/developer/system/architecture.html). When the Xen Project (https://xenproject.org/) publicly discloses a vulnerability in the Xen hypervisor, they issue a notice called a Xen security advisory (XSA) (https://xenproject.org/developers/security-policy/). Vulnerabilities in the Xen hypervisor sometimes have security implications for Qubes OS. When they do, we issue a notice called a Qubes security bulletin (QSB) (https://www.qubes-os.org/security/qsb/). (QSBs are also issued for non-Xen vulnerabilities.) However, QSBs can provide only positive confirmation that certain XSAs do affect the security of Qubes OS. QSBs cannot provide negative confirmation that other XSAs do not affect the security of Qubes OS. Therefore, we also maintain an XSA tracker (https://www.qubes-os.org/security/xsa/), which is a comprehensive list of all XSAs publicly disclosed to date, including whether each one affects the security of Qubes OS. When new XSAs are published, we add them to the XSA tracker and publish a notice like this one in order to inform Qubes users that a new batch of XSAs has been released and whether each one affects the security of Qubes OS.
QSB-115: HVM I/O port list traversal (XSA-491)
https://www.qubes-os.org/news/2026/06/09/qsb-115/
We have published Qubes Security Bulletin (QSB) 115: HVM I/O port list traversal (XSA-491) (https://github.com/QubesOS/qubes-secpack/blob/b1af9882e6723a28e75c427f499d2ddcbffaec93/QSBs/qsb-115-2026.txt). The text of this QSB and its accompanying cryptographic signatures are reproduced below, followed by a general explanation of this announcement and authentication instructions.
Qubes Security Bulletin 115
---===[ Qubes Security Bulletin 115 ]===---
2026-06-09
HVM I/O port list traversal (XSA-491)
User action
------------
Continue to update normally [1] in order to receive the security updates
described in the "Patching" section below. No other user action is
required in response to this QSB.
Summary
--------
On 2026-06-09, the Xen Project published XSA-491, "x86 HVM I/O port list
traversal" (CVE-2026-42487) [3]:
| HVM guest I/O port accesses are subject to either emulation or at
| least translation. Translations are managed by the device model (via
| XEN_DOMCTL_ioport_mapping), and hence the linked list used may changed
| at any time. Traversal of those lists (while handling guest I/O port
| accesses) therefore needs synchronizing with updates, which was
| missing so far.
Impact
-------
A malicious stub domain can crash the hypervisor (and hence the entire
system). A stub domain is a qube that accompanies a "fully-virtualized"
(HVM) qube and in which QEMU is isolated. Privilege escalation and
information leaks cannot be ruled out.
Affected systems
-----------------
All supported versions of Qubes OS are affected.
Only qubes running in HVM mode are affected. In the default
configuration, this includes sys-net and sys-usb.
Patching
---------
The following packages contain security updates that address the
vulnerabilities described in this bulletin:
For Qubes 4.2, in dom0:
- Xen packages, version 4.17.6-6
For Qubes 4.3, in dom0:
- Xen packages, version 4.19.4-9
These packages will migrate from the security-testing repository to the
current (stable) repository over the next two weeks after being tested
by the community. [2] Once available, the packages should be installed
via the Qubes Update tool or its command-line equivalents. [1]
Dom0 must be restarted afterward in order for the updates to take
effect.
If you use Anti Evil Maid, you will need to reseal your secret
passphrase to new PCR values, as PCR18+19 will change due to the new Xen
binaries.
Credits
--------
See the original Xen Security Advisory. [3]
References
-----------
[1] https://doc.qubes-os.org/en/latest/user/how-to-guides/how-to-update.html
[2] https://doc.qubes-os.org/en/latest/user/downloading-installing-upgrading/testing.html
[3] https://xenbits.xen.org/xsa/advisory-491.html
--
The Qubes Security Team
https://www.qubes-os.org/security/
Source: qsb-115-2026.txt (https://github.com/QubesOS/qubes-secpack/blob/b1af9882e6723a28e75c427f499d2ddcbffaec93/QSBs/qsb-115-2026.txt)
Marek Marczykowski-Górecki (https://www.qubes-os.org/team/#marek-marczykowski-g%C3%B3recki)’s PGP signature
-----BEGIN PGP SIGNATURE-----
iQIzBAABCAAdFiEELRdx/k12ftx2sIn61lWk8hgw4GoFAmon/JcACgkQ1lWk8hgw
4GonwA/9FXOs2RveaZ1dDShgbiYM5tdMv1I4jv4PgUKc1YAdbeW2UPpGeMoYfJ7b
YRZzyJbcxtKZ/g/zFUhI8Oz3g2GRt1zohaB7yYe1x29nWaEh++ORrFArDzBksVjo
uUGQNGvlf40vLDo0DVIgY40cSFKhU/P+R0MVz9t1oDiVCBdSt/fh8cmTDZnETB+g
41b6xa6rtienJv2SiR3jtp9Xphi3+e/v2JR9b+Ln8QMX6EpSW8fwPWwl2XGZBqD9
w9WyciGIMtRVGwesjOmH2PYmSzSZkTSER8vPTMaZw+LfAV3PHH2ccosaAZg4C+C8
ni+WUzBaqPGqa+LkujPP/Rr1dYAnUoWIH1BPsmT0/uTPt220q4ydNXR2+b4iwV6k
PmlI1BJaa7oRua9Q7BDUHJw7pGmuwUbsRwyQZJ/74aOmKF8jrq+48DMFvBnAJklz
z8dK7LlBHexumPheSHcszJtFWO7YdH8wv7SIiGrrtJWILZGGwuqJW8WhW3ZCO666
maXzl3bm5RjvYWsp4kA7REeBazz067+IXCKNWdj3CeMOj0w7Gbu4c9vDHLXsHJmV
4H8DSx0ZtHeL3NaWr559GKxY8WKCzN0j5wSPQwGRSkBnXL6CxAvKoIkKA4CJXzI/
b3k2cOVX7oFi0YdMSu0/dEsEImNKvz11bIX65l7Ii2RKLR1H1Gw=
=QiLq
https://www.qubes-os.org/news/2026/06/09/qsb-115/
We have published Qubes Security Bulletin (QSB) 115: HVM I/O port list traversal (XSA-491) (https://github.com/QubesOS/qubes-secpack/blob/b1af9882e6723a28e75c427f499d2ddcbffaec93/QSBs/qsb-115-2026.txt). The text of this QSB and its accompanying cryptographic signatures are reproduced below, followed by a general explanation of this announcement and authentication instructions.
Qubes Security Bulletin 115
---===[ Qubes Security Bulletin 115 ]===---
2026-06-09
HVM I/O port list traversal (XSA-491)
User action
------------
Continue to update normally [1] in order to receive the security updates
described in the "Patching" section below. No other user action is
required in response to this QSB.
Summary
--------
On 2026-06-09, the Xen Project published XSA-491, "x86 HVM I/O port list
traversal" (CVE-2026-42487) [3]:
| HVM guest I/O port accesses are subject to either emulation or at
| least translation. Translations are managed by the device model (via
| XEN_DOMCTL_ioport_mapping), and hence the linked list used may changed
| at any time. Traversal of those lists (while handling guest I/O port
| accesses) therefore needs synchronizing with updates, which was
| missing so far.
Impact
-------
A malicious stub domain can crash the hypervisor (and hence the entire
system). A stub domain is a qube that accompanies a "fully-virtualized"
(HVM) qube and in which QEMU is isolated. Privilege escalation and
information leaks cannot be ruled out.
Affected systems
-----------------
All supported versions of Qubes OS are affected.
Only qubes running in HVM mode are affected. In the default
configuration, this includes sys-net and sys-usb.
Patching
---------
The following packages contain security updates that address the
vulnerabilities described in this bulletin:
For Qubes 4.2, in dom0:
- Xen packages, version 4.17.6-6
For Qubes 4.3, in dom0:
- Xen packages, version 4.19.4-9
These packages will migrate from the security-testing repository to the
current (stable) repository over the next two weeks after being tested
by the community. [2] Once available, the packages should be installed
via the Qubes Update tool or its command-line equivalents. [1]
Dom0 must be restarted afterward in order for the updates to take
effect.
If you use Anti Evil Maid, you will need to reseal your secret
passphrase to new PCR values, as PCR18+19 will change due to the new Xen
binaries.
Credits
--------
See the original Xen Security Advisory. [3]
References
-----------
[1] https://doc.qubes-os.org/en/latest/user/how-to-guides/how-to-update.html
[2] https://doc.qubes-os.org/en/latest/user/downloading-installing-upgrading/testing.html
[3] https://xenbits.xen.org/xsa/advisory-491.html
--
The Qubes Security Team
https://www.qubes-os.org/security/
Source: qsb-115-2026.txt (https://github.com/QubesOS/qubes-secpack/blob/b1af9882e6723a28e75c427f499d2ddcbffaec93/QSBs/qsb-115-2026.txt)
Marek Marczykowski-Górecki (https://www.qubes-os.org/team/#marek-marczykowski-g%C3%B3recki)’s PGP signature
-----BEGIN PGP SIGNATURE-----
iQIzBAABCAAdFiEELRdx/k12ftx2sIn61lWk8hgw4GoFAmon/JcACgkQ1lWk8hgw
4GonwA/9FXOs2RveaZ1dDShgbiYM5tdMv1I4jv4PgUKc1YAdbeW2UPpGeMoYfJ7b
YRZzyJbcxtKZ/g/zFUhI8Oz3g2GRt1zohaB7yYe1x29nWaEh++ORrFArDzBksVjo
uUGQNGvlf40vLDo0DVIgY40cSFKhU/P+R0MVz9t1oDiVCBdSt/fh8cmTDZnETB+g
41b6xa6rtienJv2SiR3jtp9Xphi3+e/v2JR9b+Ln8QMX6EpSW8fwPWwl2XGZBqD9
w9WyciGIMtRVGwesjOmH2PYmSzSZkTSER8vPTMaZw+LfAV3PHH2ccosaAZg4C+C8
ni+WUzBaqPGqa+LkujPP/Rr1dYAnUoWIH1BPsmT0/uTPt220q4ydNXR2+b4iwV6k
PmlI1BJaa7oRua9Q7BDUHJw7pGmuwUbsRwyQZJ/74aOmKF8jrq+48DMFvBnAJklz
z8dK7LlBHexumPheSHcszJtFWO7YdH8wv7SIiGrrtJWILZGGwuqJW8WhW3ZCO666
maXzl3bm5RjvYWsp4kA7REeBazz067+IXCKNWdj3CeMOj0w7Gbu4c9vDHLXsHJmV
4H8DSx0ZtHeL3NaWr559GKxY8WKCzN0j5wSPQwGRSkBnXL6CxAvKoIkKA4CJXzI/
b3k2cOVX7oFi0YdMSu0/dEsEImNKvz11bIX65l7Ii2RKLR1H1Gw=
=QiLq
-----END PGP SIGNATURE-----
Source: qsb-115-2026.txt.sig.marmarek (https://github.com/QubesOS/qubes-secpack/blob/b1af9882e6723a28e75c427f499d2ddcbffaec93/QSBs/qsb-115-2026.txt.sig.marmarek)
Simon Gaiser (aka HW42) (https://www.qubes-os.org/team/#simon-gaiser-aka-hw42)’s PGP signature
-----BEGIN PGP SIGNATURE-----
iQIzBAABCgAdFiEE6hjn8EDEHdrv6aoPSsGN4REuFJAFAmom9IMACgkQSsGN4REu
FJDxHw/+KDCeF8EeMZ2AidWz0gtj2aCWe9MkZ2iSrof69dztym8zkYW3TrKovQuT
aTiZBL/NmEOGivpgx5oWXf/R8MRzY222sIm3d+Bqpt5ki3osG6DM0rH42IqTeLuk
w1yg2N239yv9Fjf0mJ7Q3JF3lP+skHe/JdP8IXxgiKIsYfC7GrKHUq/EZGWJPBXd
qz548E5pZJrlyheulJaqEl+aXdzPpY76ERgVjkgfLGoapKgyRFOt075MQUMaa75H
RXQiypmjovmEUVdxnMQDXC2MGzu1qDdJHItEsLY9PCYnGI2wn7MwKltbGa/ey4IZ
a4q8QMcp20Q/rFDQ+MAl1troGz0FUyyYG+YUeOPTFC5IeXlHakhc7P+fjg4vqPXi
637XwAip51RQAXvGWSaOPMULsUXfI8wnxYBtEYhhxjKzYLR0jAhuqEpBFl0YIS50
qNiS1QFsHv1S9Tqi1mWL9eCvnzUotGsGlErtMqWf4W47Wz97WHZgVH7L61Lw9szn
kIN/WzJxL3M+aM838OQUPEEAoichnaJFfg6iPJd+cLHHgiptkg8fu9Cb3zpmrLMr
tDm8AQs2wtLiZnAm4yVDRrddiFUzBs7LEDSkRJkv8ZDvdeDtl0pkLscE9k4FjbFa
1mYklLru/GNO/uq6hOzQiFwTlb7LqyJKdLqIPeevwjYl3GxLM4A=
=84mQ
-----END PGP SIGNATURE-----
Source: qsb-115-2026.txt.sig.simon (https://github.com/QubesOS/qubes-secpack/blob/b1af9882e6723a28e75c427f499d2ddcbffaec93/QSBs/qsb-115-2026.txt.sig.simon)
What is the purpose of this announcement?
The purpose of this announcement is to inform the Qubes community that a new Qubes security bulletin (QSB) has been published.
What is a Qubes security bulletin (QSB)?
A Qubes security bulletin (QSB) (https://www.qubes-os.org/security/qsb/) is a security announcement issued by the Qubes security team (https://doc.qubes-os.org/en/latest/project-security/security.html#qubes-security-team). A QSB typically provides a summary and impact analysis of one or more recently-discovered software vulnerabilities, including details about patching to address them.
Why should I care about QSBs?
QSBs tell you what actions you must take in order to protect yourself from recently-discovered security vulnerabilities. In most cases, security vulnerabilities are addressed by updating normally (https://doc.qubes-os.org/en/latest/user/how-to-guides/how-to-update.html). However, in some cases, special user action is required. In all cases, the required actions are detailed in QSBs.
What are the PGP signatures that accompany QSBs?
A PGP (https://en.wikipedia.org/wiki/Pretty_Good_Privacy) signature is a cryptographic digital signature (https://en.wikipedia.org/wiki/Digital_signature) made in accordance with the OpenPGP (https://en.wikipedia.org/wiki/Pretty_Good_Privacy#OpenPGP) standard. PGP signatures can be cryptographically verified with programs like GNU Privacy Guard (GPG) (https://gnupg.org/). The Qubes security team cryptographically signs all QSBs so that Qubes users have a reliable way to check whether QSBs are genuine. The only way to be certain that a QSB is authentic is by verifying its PGP signatures.
Why should I care whether a QSB is authentic?
A forged QSB could deceive you into taking actions that adversely affect the security of your Qubes OS system, such as installing malware or making configuration changes that render your system vulnerable to attack. Falsified QSBs could sow fear, uncertainty, and doubt about the security of Qubes OS or the status of the Qubes OS Project.
How do I verify the PGP signatures on a QSB?
The following command-line instructions assume a Linux system with git and gpg installed. (For Windows and Mac options, see OpenPGP software (https://doc.qubes-os.org/en/latest/project-security/verifying-signatures.html#openpgp-software).)
Obtain the Qubes Master Signing Key (QMSK), e.g.:
$ gpg --fetch-keys https://keys.qubes-os.org/keys/qubes-master-signing-key.asc
gpg: directory '/home/user/.gnupg' created
gpg: keybox '/home/user/.gnupg/pubring.kbx' created
gpg: requesting key from 'https://keys.qubes-os.org/keys/qubes-master-signing-key.asc'
gpg: /home/user/.gnupg/trustdb.gpg: trustdb created
Source: qsb-115-2026.txt.sig.marmarek (https://github.com/QubesOS/qubes-secpack/blob/b1af9882e6723a28e75c427f499d2ddcbffaec93/QSBs/qsb-115-2026.txt.sig.marmarek)
Simon Gaiser (aka HW42) (https://www.qubes-os.org/team/#simon-gaiser-aka-hw42)’s PGP signature
-----BEGIN PGP SIGNATURE-----
iQIzBAABCgAdFiEE6hjn8EDEHdrv6aoPSsGN4REuFJAFAmom9IMACgkQSsGN4REu
FJDxHw/+KDCeF8EeMZ2AidWz0gtj2aCWe9MkZ2iSrof69dztym8zkYW3TrKovQuT
aTiZBL/NmEOGivpgx5oWXf/R8MRzY222sIm3d+Bqpt5ki3osG6DM0rH42IqTeLuk
w1yg2N239yv9Fjf0mJ7Q3JF3lP+skHe/JdP8IXxgiKIsYfC7GrKHUq/EZGWJPBXd
qz548E5pZJrlyheulJaqEl+aXdzPpY76ERgVjkgfLGoapKgyRFOt075MQUMaa75H
RXQiypmjovmEUVdxnMQDXC2MGzu1qDdJHItEsLY9PCYnGI2wn7MwKltbGa/ey4IZ
a4q8QMcp20Q/rFDQ+MAl1troGz0FUyyYG+YUeOPTFC5IeXlHakhc7P+fjg4vqPXi
637XwAip51RQAXvGWSaOPMULsUXfI8wnxYBtEYhhxjKzYLR0jAhuqEpBFl0YIS50
qNiS1QFsHv1S9Tqi1mWL9eCvnzUotGsGlErtMqWf4W47Wz97WHZgVH7L61Lw9szn
kIN/WzJxL3M+aM838OQUPEEAoichnaJFfg6iPJd+cLHHgiptkg8fu9Cb3zpmrLMr
tDm8AQs2wtLiZnAm4yVDRrddiFUzBs7LEDSkRJkv8ZDvdeDtl0pkLscE9k4FjbFa
1mYklLru/GNO/uq6hOzQiFwTlb7LqyJKdLqIPeevwjYl3GxLM4A=
=84mQ
-----END PGP SIGNATURE-----
Source: qsb-115-2026.txt.sig.simon (https://github.com/QubesOS/qubes-secpack/blob/b1af9882e6723a28e75c427f499d2ddcbffaec93/QSBs/qsb-115-2026.txt.sig.simon)
What is the purpose of this announcement?
The purpose of this announcement is to inform the Qubes community that a new Qubes security bulletin (QSB) has been published.
What is a Qubes security bulletin (QSB)?
A Qubes security bulletin (QSB) (https://www.qubes-os.org/security/qsb/) is a security announcement issued by the Qubes security team (https://doc.qubes-os.org/en/latest/project-security/security.html#qubes-security-team). A QSB typically provides a summary and impact analysis of one or more recently-discovered software vulnerabilities, including details about patching to address them.
Why should I care about QSBs?
QSBs tell you what actions you must take in order to protect yourself from recently-discovered security vulnerabilities. In most cases, security vulnerabilities are addressed by updating normally (https://doc.qubes-os.org/en/latest/user/how-to-guides/how-to-update.html). However, in some cases, special user action is required. In all cases, the required actions are detailed in QSBs.
What are the PGP signatures that accompany QSBs?
A PGP (https://en.wikipedia.org/wiki/Pretty_Good_Privacy) signature is a cryptographic digital signature (https://en.wikipedia.org/wiki/Digital_signature) made in accordance with the OpenPGP (https://en.wikipedia.org/wiki/Pretty_Good_Privacy#OpenPGP) standard. PGP signatures can be cryptographically verified with programs like GNU Privacy Guard (GPG) (https://gnupg.org/). The Qubes security team cryptographically signs all QSBs so that Qubes users have a reliable way to check whether QSBs are genuine. The only way to be certain that a QSB is authentic is by verifying its PGP signatures.
Why should I care whether a QSB is authentic?
A forged QSB could deceive you into taking actions that adversely affect the security of your Qubes OS system, such as installing malware or making configuration changes that render your system vulnerable to attack. Falsified QSBs could sow fear, uncertainty, and doubt about the security of Qubes OS or the status of the Qubes OS Project.
How do I verify the PGP signatures on a QSB?
The following command-line instructions assume a Linux system with git and gpg installed. (For Windows and Mac options, see OpenPGP software (https://doc.qubes-os.org/en/latest/project-security/verifying-signatures.html#openpgp-software).)
Obtain the Qubes Master Signing Key (QMSK), e.g.:
$ gpg --fetch-keys https://keys.qubes-os.org/keys/qubes-master-signing-key.asc
gpg: directory '/home/user/.gnupg' created
gpg: keybox '/home/user/.gnupg/pubring.kbx' created
gpg: requesting key from 'https://keys.qubes-os.org/keys/qubes-master-signing-key.asc'
gpg: /home/user/.gnupg/trustdb.gpg: trustdb created